clj-holmes / clj-watson

clojure deps SCA
Eclipse Public License 2.0
77 stars 8 forks source link

Add `--cvss-fail-threshold` #123

Closed lread closed 1 week ago

lread commented 2 weeks ago

See README for general description.

New option is mutually exclusive to --fail-on-result; if both are specified, clj-watson fails fast with usage error and help.

Conservatively derives score when missing or suspicious looking:

Also:

Closes #114

lread commented 2 weeks ago

Thanks for taking a peek @coyotesqrl. I think this matches what we discussed. If you have any other feedback, happy to hear it!

lread commented 1 week ago

@seancorfield when you have some time and some interest, this PR awaits your review.

seancorfield commented 1 week ago

Sorry, last week got completely derailed which was when I said I would review this...

lread commented 1 week ago

Thanks! And no problem @seancorfield, I understand that folks get busy and distracted!